CVE-2023-32559

CVSS v3.1 7.5 (High)
75% Progress
EPSS 0.08 % (35th)
0.08% Progress
Affected Products 1
Advisories 27

A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API process.binding() can bypass the policy mechanism by requiring internal modules and eventually take advantage of process.binding('spawn_sync') run arbitrary code, outside of the limits defined in a policy.json file. Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js.

Weaknesses
CWE-NVD-noinfo
CVE Status
PUBLISHED
CNA
HackerOne
Published Date
2023-08-24 02:15:09
(12 months ago)
Updated Date
2023-10-24 17:48:55
(10 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Nodejs Node.js from 16.0.0 version and 16.20.1 and prior versions cpe:2.3:a:nodejs:node.js::*:*:*:- >= 16.0.0 <= 16.20.1
  Nodejs Node.js from 18.0.0 version and 18.17.0 and prior versions cpe:2.3:a:nodejs:node.js::*:*:*:- >= 18.0.0 <= 18.17.0
  Nodejs Node.js from 20.0.0 version and 20.5.0 and prior versions cpe:2.3:a:nodejs:node.js::*:*:*:- >= 20.0.0 <= 20.5.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...